job summary:Our client in the Sacramento area has a 18+ month contract opportunity for an Principal Information Security Auditor. This position has the potential to convert. Remote role. General SummaryThe Principal Information Security Auditor is responsible for leading, developing and completing integrated internal audits in compliance with departmental and professional standards. Acts as the principal technical leader for auditing complex information security technologies, assessing security frameworks, security and privacy architecture designs, regulatory and business risk management, security and privacy incident management, application and system change control vulnerability management.Essential FunctionsDevelops IT, cybersecurity and privacy audit programs and special consulting projects, leads audit testing and CAP reviews, and delivers audit reports to audit managementLead and/or participate in complex information technology audits of IT areas to assess the adequacy of internal controls and compliance with Company and departmental goals, objectives and standardsPerform and document audit activities utilizing a comprehensive audit approach (policies, procedures, processes, controls and measures) to address financial, compliance, IT and operational risks in accordance with professional standardsResearches and interprets governmental laws, regulations, and compliance requirements for reviewJob SpecificationsTypically has the following skills or abilities:Bachelor's degree in management information system or computer science or engineering, or related field or equivalent experience.8+ years of hands-on technical information security/privacy experience.One existing certification (or equivalent) from each of the following categories, which must be currently maintained and valid.General Audit Certification: Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certified Fraud Examiner (CFE)IT Audit Certification: Information Technology Infrastructure Library (ITIL), Certified Information Systems Auditor (CISA), Certified in Risk and Information System Control (CRISC), Certified in Risk Management Assurance (CRMA), Certified in Governance of Enterprise IT (CGEIT), Cisco Certified Network Associate/Professional (CCNA, CCNP)IT Security/Privacy Certification: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Quality Security Assessor (QSA), Payment Card Industry Professional (PCIP), Certified Ethical Hacker (CEH), Microsoft Certified Professional/Security Engineer (MCP, MCSE)Expert level knowledge of security principles and technologies with5+ years hands-on experience in information technology systems and security assessments or security by design testingBig 4 or equivalent regulatory compliance consulting experience applying broad risk and threat assessment methodology experience across information technology, security, privacy and businessDemonstrated leadership skills in identifying and analyzing regulatory, security and privacy vulnerabilities in the following:Finance regulatory compliance testing such as NAIC/MAR, SOX, EHNCA, ICFR or equivalent.Information technology compliance testing such as ISO27001/2013, COSO, AICPA/SOC(I,II,III) or equivalent.Information security compliance testing such as CMS ARS, CIS, CSA or equivalent.Information privacy compliance testing such as HIPAA (45 CFR), GDPR, CCPA, NYCRR or equivalent.GRC frameworks such as NIST (800-36), ISO (27k series), COBIT, ITIL, GAAS or equivalent.Compliance crosswalk methodologies and models such as SCF, CCF, UCF, RMF, HITRUST or equivalent.Proven leadership with multiple cross-functional teams in a deadline-driven environmentExcellent written reporting and presentation skillsAbility to travel approximately 25% of the timeClean credit history as reported by credit reportWorking ConditionsThe working environment is generally favorable. Lighting and temperature are adequate, and there are no hazardous or unpleasant conditions caused by noise, dust etc.The above information in this description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted a location: Rancho Cordova, Californiajob type: Contractsalary: $45 - 70 per hourwork hours: 8am to 5pmeducation: Bachelors responsibilities:information security auditing qualifications:Experience level: ExperiencedMinimum 8 years of experienceEducation: Bachelors skills: security auditingprivacy compliance security complianceEqual Opportunity Employer: Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status. Qualified applicants in San Francisco with criminal histories will be considered for employment in accordance with the San Francisco Fair Chance Ordinance. We will consider for employment all qualified Applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance.